Cross-site scripting (XSS) vulnerability in Nodez 4.6.1.1 allows remote attackers to inject arbitrary web script or HTML via the op parameter. NOTE: it is possible that this issue is resultant from the directory traversal vulnerability.
https://exchange.xforce.ibmcloud.com/vulnerabilities/25121
http://www.vupen.com/english/advisories/2006/0899